6.1

CVSS4.0

CVE-2026-5774 - Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map

Improper synchronization of the userTokens map in the API server in Canonical JujuΒ 4.0.5,Β 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

πŸ“… Published: April 10, 2026, 12:10 p.m. πŸ”„ Last Modified: April 10, 2026, 12:10 p.m.

8.7

CVSS4.0

CVE-2026-5777 - Security Misconfiguration Vulnerability in Atom 3x Projector

This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading…

πŸ“… Published: April 10, 2026, 11:40 a.m. πŸ”„ Last Modified: April 10, 2026, 11:40 a.m.

0.0

CVE-2026-39304 - Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect han…

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes t…

πŸ“… Published: April 10, 2026, 10:54 a.m. πŸ”„ Last Modified: April 10, 2026, 10:54 a.m.

0.0

CVE-2026-31412 - usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks() The `check_command_size_in_blocks()` function calculates the data size in bytes by left shifting `common->data_size_from_cmnd` by the b…

πŸ“… Published: April 10, 2026, 10:35 a.m. πŸ”„ Last Modified: April 10, 2026, 10:35 a.m.

7.1

CVSS3.1

CVE-2026-4162 - Gravity SMTP <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall

The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and…

πŸ“… Published: April 10, 2026, 9:25 a.m. πŸ”„ Last Modified: April 10, 2026, 9:25 a.m.

8.1

CVSS3.1

CVE-2021-47961 -

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined…

πŸ“… Published: April 10, 2026, 9:22 a.m. πŸ”„ Last Modified: April 10, 2026, 9:22 a.m.

6.5

CVSS3.1

CVE-2021-47960 -

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page,…

πŸ“… Published: April 10, 2026, 9:21 a.m. πŸ”„ Last Modified: April 10, 2026, 9:21 a.m.

0.0

CVE-2026-6057 - Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

πŸ“… Published: April 10, 2026, 9:16 a.m. πŸ”„ Last Modified: April 10, 2026, 9:16 a.m.

4.8

CVSS4.0

CVE-2026-6042 - musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix th…

πŸ“… Published: April 10, 2026, 9 a.m. πŸ”„ Last Modified: April 10, 2026, 3:54 p.m.

6.9

CVSS4.0

CVE-2026-6038 - code-projects Vehicle Showroom Management System RegisterCustomerFunction.php sql injection

A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument BRANCH_ID leads to sql injection. The attack may be performed from remote. The exploit is public…

πŸ“… Published: April 10, 2026, 8:45 a.m. πŸ”„ Last Modified: April 10, 2026, 8:45 a.m.
Total resulsts: 343850
Page 10 of 34,385
Β« previous page Β» next page
Filters